漏洞标题
思科Firepower威胁防御软件和管理中心代码注入漏洞
漏洞描述信息
设备运行Cisco火力防御软件(FTD)和设备运行Cisco火力管理软件(FMC)之间存在一个漏洞,该漏洞可能导致已验证的本地攻击者在一个受影响设备的潜在操作系统内核中执行具有root权限的任意命令。该漏洞是由于对用户输入的验证不足。攻击者可以通过访问受影响设备的专家模式,向连接的系统提交特定命令来利用此漏洞。如果攻击者具有关联的FTD设备的管理员权限,则成功利用此漏洞可以让攻击者在一个FMC设备上下文中执行任意代码。否则,如果攻击者具有关联的FMC设备的管理员权限,则成功利用此漏洞可以让攻击者在一个FTD设备上下文中执行任意代码。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
漏洞标题
Cisco Cisco Firepower Threat Defense Software and Cisco Firepower Management Center Code Injection Vulnerability
漏洞描述信息
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by accessing the expert mode of an affected device and submitting specific commands to a connected system. A successful exploit could allow the attacker to execute arbitrary code in the context of an FMC device if the attacker has administrative privileges on an associated FTD device. Alternatively, a successful exploit could allow the attacker to execute arbitrary code in the context of an FTD device if the attacker has administrative privileges on an associated FMC device.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
漏洞类别
对生成代码的控制不恰当(代码注入)
漏洞标题
Cisco Firepower Threat Defense 安全漏洞
漏洞描述信息
Cisco Firepower Threat Defense(FTD)是美国思科(Cisco)公司的一套提供下一代防火墙服务的统一软件。 Cisco Firepower Threat Defense、Firepower Management Center存在安全漏洞,该漏洞源于对用户提供的输入验证不足,攻击者利用该漏洞可以在受影响的设备上使用root权限执行任意命令。
CVSS信息
N/A
漏洞类别
其他